CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 100.0% of known CVEs.
Jul 07, 2025
Jul 28, 2025
Threat Analysis
PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Remediation Directive
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
External Intelligence
This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see:
https://github.com/PHPMailer/PHPMailer/releases/tag/v5.2.18
https://github.com/advisories/GHSA-5f37-gxvh-23v6
https://github.com/advisories/GHSA-5f37-gxvh-23v6
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2016-10033